CVE-2019-8708Apple Macos vulnerability

6 documents4 sources
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 81.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateMay 24

Description

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Catalina 10.15, iOS 13. A local user may be able to check for the existence of arbitrary files.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5apple/macosunspecified10.15
NVDapple/mac_os_x< 10.15
CVEListV5apple/iosunspecified13
NVDapple/iphone_os< 13.0

🔴Vulnerability Details

2
GHSA
GHSA-8v4h-ffp9-65q7: A logic issue was addressed with improved restrictions2022-05-24
CVEList
CVE-2019-8708: A logic issue was addressed with improved restrictions2020-10-27

📋Vendor Advisories

3
Apple
CVE-2019-8708: macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-0062019-10-29
Apple
CVE-2019-8708: macOS Catalina 10.152019-10-07
Apple
CVE-2019-8708: iOS 132019-09-19
CVE-2019-8708 — Apple Macos vulnerability | cvebase